SemantiqWall
PT EN
Sign in I'm a vendor
Security

Responsible disclosure policy

Found a vulnerability in SemantiqWall? Thank you for letting us know. Good-faith security research within these rules is authorized and welcome.

Scope

The website and dashboard at semantiqwall.com, the API used by customers' agents and the SemantiqWall PHP and TypeScript SDKs.

Out of scope: third-party services we use (hosting, email) and our customers' systems.

Our timelines

We acknowledge your report within 3 business days, keep you informed until it's fixed and agree on the disclosure date with you.

Testing rules

If you act in good faith within these rules, we won't take legal action against you, and we'll publicly credit your contribution if you'd like.

Security advisories and CVEs

When a critical or high-severity flaw affects customers, we publish an advisory on this page after the fix, with the weakness type (CWE), what was affected, since when and what customers need to do. When the flaw is in something customers install (the SDKs), or whenever the CVE program rules call for it, we request a CVE ID and provide accurate CWE and CPE fields.

Advisories published so far: none.

See how SemantiqWall follows CISA's Secure by Design goals

See our security program policies in the Trust Center